Data breach
newyorkfestivals.com
- Records
- 1,063,223
- Breach date
- 1 January 2020Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 puts you at serious risk
- Email addresses1,063,223
- Passwords1,054,920
About this breach
The investigation team has indexed a data breach tied to newyorkfestivals.com, the website of the international awards organization. The listing covers roughly 1.06 million accounts, each associated with an email address and, in the overwhelming majority of records, a password. Our investigation team estimates the breach occurred on or around January 1, 2020, though no exact attack method has been verified. The records were added to our index on December 1, 2024, and no individual or group has publicly claimed responsibility for the breach.
Limited public reporting: As of September 25, 2026, detailed company notices or major news coverage for this listing were limited in sources reviewed. The facts below rely primarily on the indexed fields plus any secondary sources cited.
What Information Was Compromised?
Our analysis found the following data types in this breach:
Email addresses in 1,063,223 records
Passwords in 1,049,200 records
The password count is slightly lower than the email count, meaning some accounts appear without an associated credential. The listing does not specify whether passwords were stored in plaintext or hashed, and no other data types such as names, phone numbers, or payment details were identified in the indexed records.
Not every individual is affected by every type of data listed here.
What Are the Potential Risks for Affected Individuals?
Exposed email and password pairs are most dangerous when people reuse passwords across multiple sites. If you used the same password on newyorkfestivals.com as on your email account, banking site, or social media, an attacker who obtains the data could try those credentials elsewhere.
Attackers commonly use large credential dumps for a tactic called credential stuffing, where automated tools test the same email and password combinations across hundreds of popular services until one works. Even accounts with unique passwords carry some risk: an exposed email address can be used to send targeted phishing emails that appear more convincing because they reference real services or accounts.
The breach dates to around January 2020, so any passwords that were exposed and never changed should be treated as compromised, even if the account itself was not abused in the years since.
What Should You Do If You Were Affected?
There are several practical steps you can take if your information appears in this breach:
Change your password for any account associated with newyorkfestivals.com. If you reused that password anywhere else, change it there too.
Enable two-factor authentication wherever it is offered, starting with your primary email account. This can block access even if a password is known.
Watch for phishing. Be cautious with emails referencing your account, award entries, or payment requests, and avoid clicking links in unexpected messages.
Check your other accounts for suspicious activity, such as password-reset notices you did not request.
Even if you no longer use the service, changing a reused password still matters, because old credentials remain useful to attackers targeting other websites.
